BetterGov: Government’s biggest cybersecurity risk is its reactive mindset
BetterGov.ph has raised concerns over what it sees as a reactive approach to cybersecurity in government, where weaknesses are addressed largely after an attack has already happened.
Following the hacking of several government websites this week, BetterGov called for cybersecurity to become a continuous government program rather than a series of fixes triggered by individual incidents.
“What’s needed: regular security checkups, faster fixes, and clear public updates. Not a one-time patch,” BetterGov said in a Facebook post.
The statement came after several Philippine government websites, including the Bureau of Internal Revenue (BIR), were hacked on September 8. Homepages were defaced and subsequently restored, while authorities said taxpayer records and core systems were not compromised based on initial assessments.
BetterGov noted that this was not the first time government websites had been attacked and cautioned that assurances that data is safe do not address the broader cybersecurity problem.
“This isn’t the first time gov’t sites have been hacked, and ‘your data is safe’ isn’t the full picture,” the group said.
The Department of Information and Communications Technology (DICT) and the Cybercrime Investigation and Coordinating Center (CICC) responded to the latest incidents by directing government agencies to conduct cybersecurity assessments and strengthen their defenses.
Agencies were told to identify critical vulnerabilities, apply patches, strengthen account security, review systems exposed to the internet and improve incident response and recovery measures.
The Philippine National Police Anti-Cybercrime Group is also working with government cybersecurity authorities to trace those behind the attacks and determine how the breaches occurred.
The response addresses the immediate threat, but BetterGov’s warning points to the larger challenge: cybersecurity checks and fixes should already be part of the normal operations of government agencies before hackers expose weaknesses.
For BetterGov, cybersecurity cannot be reduced to attack, investigate, restore and repeat.
Government needs to find the vulnerabilities first.
